Keeper Security - SAML Relying Party Configuration - RSA Ready Implementation Guide
2 years ago
This article describes how to integrate RSA with Keeper Security using SAML Relying Party.

Configure RSA Cloud Authentication Service

Perform these steps to configure RSA Cloud Authentication Service as Relying Party to Keeper Security.

Procedure
  1. Sign in to the RSA Cloud Administration Console with administrator credentials.
  2. Click Authentication Clients > Relying Parties on the menu at the top of the screen.image.png
  3. Click Add a Relying Party.  
  4. In the Relying Party Catalog, click Add corresponding to Service Provider SAML.                                                                             image.png        
  5. On the Basic Information page, enter the name for the application in the Name field and click Next Step.image.png
  6. On the Authentication page, choose SecurID manages all authentication.
  7. Select a Primary Authentication Method and Access Policy as required and click Next Step.image.png
  8. For providing Service Provider details select Import Metadata and click Choose File. Select the file that is downloaded from the Service Provider.
    See the Configure Keeper Security section in this article to obtain metadata file. image.png
  9. Review the ACS URL and Service Provider Entity ID values that will be auto-filled.image.png
  10. In the SAML Response Protection section, choose IdP signs assertion within response.
  11. Click Download Certificate to download the certificate.image.png
  12. Select Show Advanced Configuration, under the User Identity section select Auto Detect in the Identifier Type and Property from the options in the drop-down.                                                                                                                                                                            image.png
  13. Under the Statement Attribute section add the following Attribute.image.png
  14. Click Save and Finish.
  15. Go to the My Relying Parties page and choose Metadata from the Edit dropdown menu to download the metadata.image.png
  16. Click Publish Changes. After publishing, your application is now enabled for SSO.image.png

Configure Keeper Security 

Perform these steps to configure Keeper Security.
  1. Login to Keeper Security admin console.
  2. Click on Admin, under Node section click on Add Node.image.png
  3. Provide a Name and click Add Node.                                                                                                                                                                              image.png
  4. Under the Provisioning section click on Add Method.image.png
  5. Select Single Sign-On with SSO Connect Cloud and click Next.image.png
  6. Provide a Configuration Name and Enterprise Domain - typically this will be your company name, the Enterprise Domain name needs to be unique, then click on Save.                                                                                                                                                                                               image.png
  7. Under the Identity Provider section, click on Browse Files and upload the metadata file downloaded from the RSA platform.image.png
  8. Go back to the Provisioning page by clicking the arrow.image.png
  9. Click on View.                                                         image.png
  10. Click on Export Metadata to download the metadata file (this file will be used to configure the RSA platform).image.png
The configuration is complete.
Return to Keeper Security - RSA Ready Implementation Guide.